undefect. CWE-407 — 63 sites patched across 27 ecosystems
Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com Patches, unit tests, benchmarks, whitepaper, and outreach briefs. Public domain — no copyright claimed. Use freely.
This commit is contained in:
commit
0a580b313d
70422 changed files with 17213626 additions and 0 deletions
58
test/jdk/java/net/UnixDomainSocketAddress/AddressTest.java
Normal file
58
test/jdk/java/net/UnixDomainSocketAddress/AddressTest.java
Normal file
|
|
@ -0,0 +1,58 @@
|
|||
/*
|
||||
* Copyright (c) 2020, 2024, Oracle and/or its affiliates. All rights reserved.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License version 2 only, as
|
||||
* published by the Free Software Foundation.
|
||||
*
|
||||
* This code is distributed in the hope that it will be useful, but WITHOUT
|
||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* version 2 for more details (a copy is included in the LICENSE file that
|
||||
* accompanied this code).
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License version
|
||||
* 2 along with this work; if not, write to the Free Software Foundation,
|
||||
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
*
|
||||
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
||||
* or visit www.oracle.com if you need additional information or have any
|
||||
* questions.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @test
|
||||
* @bug 8231358
|
||||
* @compile ../../nio/file/spi/testfsp/testfsp/TestProvider.java AddressTest.java
|
||||
* @run testng/othervm AddressTest
|
||||
*/
|
||||
|
||||
import java.net.UnixDomainSocketAddress;
|
||||
import java.net.URI;
|
||||
import java.nio.file.FileSystems;
|
||||
import java.nio.file.spi.FileSystemProvider;
|
||||
import java.nio.file.Path;
|
||||
|
||||
import org.testng.annotations.Test;
|
||||
|
||||
import static org.testng.Assert.assertThrows;
|
||||
|
||||
/**
|
||||
* Verify that UnixDomainSocketAddress.of(path) throws IAE
|
||||
* if given a Path that does not originate from system default
|
||||
* file system.
|
||||
*/
|
||||
public class AddressTest {
|
||||
|
||||
// Expected exception
|
||||
private static final Class<IllegalArgumentException> IAE =
|
||||
IllegalArgumentException.class;
|
||||
|
||||
@Test
|
||||
public static void runTest() throws Exception {
|
||||
var fsp = new testfsp.TestProvider(FileSystems.getDefault().provider());
|
||||
Path path = fsp.getPath(URI.create("file:/"));
|
||||
assertThrows(IAE, () -> UnixDomainSocketAddress.of(path));
|
||||
}
|
||||
}
|
||||
85
test/jdk/java/net/UnixDomainSocketAddress/LengthTest.java
Normal file
85
test/jdk/java/net/UnixDomainSocketAddress/LengthTest.java
Normal file
|
|
@ -0,0 +1,85 @@
|
|||
/*
|
||||
* Copyright (c) 2020, Oracle and/or its affiliates. All rights reserved.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License version 2 only, as
|
||||
* published by the Free Software Foundation.
|
||||
*
|
||||
* This code is distributed in the hope that it will be useful, but WITHOUT
|
||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* version 2 for more details (a copy is included in the LICENSE file that
|
||||
* accompanied this code).
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License version
|
||||
* 2 along with this work; if not, write to the Free Software Foundation,
|
||||
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
*
|
||||
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
||||
* or visit www.oracle.com if you need additional information or have any
|
||||
* questions.
|
||||
*/
|
||||
|
||||
/*
|
||||
* @test
|
||||
* @summary Test UnixDomainSocketAddress constructor
|
||||
* @library /test/lib
|
||||
* @run testng/othervm LengthTest
|
||||
*/
|
||||
|
||||
import org.testng.annotations.DataProvider;
|
||||
import org.testng.annotations.Test;
|
||||
|
||||
import static java.lang.System.out;
|
||||
import static java.net.StandardProtocolFamily.UNIX;
|
||||
import static jdk.test.lib.Asserts.assertTrue;
|
||||
|
||||
import java.net.UnixDomainSocketAddress;
|
||||
import java.io.IOException;
|
||||
import java.nio.channels.SocketChannel;
|
||||
import java.nio.file.Path;
|
||||
|
||||
public class LengthTest {
|
||||
final int namelen = 100; // length close to max
|
||||
|
||||
@DataProvider(name = "strings")
|
||||
public Object[][] strings() {
|
||||
if (namelen == -1)
|
||||
return new Object[][] {new String[]{""}};
|
||||
|
||||
return new Object[][]{
|
||||
{""},
|
||||
{new String(new char[100]).replaceAll("\0", "x")},
|
||||
{new String(new char[namelen]).replaceAll("\0", "x")},
|
||||
{new String(new char[namelen-1]).replaceAll("\0", "x")},
|
||||
};
|
||||
}
|
||||
|
||||
@Test(dataProvider = "strings")
|
||||
public void expectPass(String s) {
|
||||
var addr = UnixDomainSocketAddress.of(s);
|
||||
assertTrue(addr.getPath().toString().equals(s), "getPathName.equals(s)");
|
||||
var p = Path.of(s);
|
||||
addr = UnixDomainSocketAddress.of(p);
|
||||
assertTrue(addr.getPath().equals(p), "getPath.equals(p)");
|
||||
}
|
||||
|
||||
@Test
|
||||
public void expectNPE() {
|
||||
try {
|
||||
String s = null;
|
||||
UnixDomainSocketAddress.of(s);
|
||||
throw new RuntimeException("Expected NPE");
|
||||
} catch (NullPointerException npe) {
|
||||
out.println("\tCaught expected exception: " + npe);
|
||||
}
|
||||
try {
|
||||
Path p = null;
|
||||
UnixDomainSocketAddress.of(p);
|
||||
throw new RuntimeException("Expected NPE");
|
||||
} catch (NullPointerException npe) {
|
||||
out.println("\tCaught expected exception: " + npe);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
@ -0,0 +1,125 @@
|
|||
/*
|
||||
* Copyright (c) 2020, Oracle and/or its affiliates. All rights reserved.
|
||||
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
||||
*
|
||||
* This code is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License version 2 only, as
|
||||
* published by the Free Software Foundation.
|
||||
*
|
||||
* This code is distributed in the hope that it will be useful, but WITHOUT
|
||||
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
||||
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* version 2 for more details (a copy is included in the LICENSE file that
|
||||
* accompanied this code).
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License version
|
||||
* 2 along with this work; if not, write to the Free Software Foundation,
|
||||
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||
*
|
||||
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
||||
* or visit www.oracle.com if you need additional information or have any
|
||||
* questions.
|
||||
*/
|
||||
|
||||
import org.testng.annotations.Test;
|
||||
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.DataOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.InvalidObjectException;
|
||||
import java.io.ObjectInputStream;
|
||||
import java.io.ObjectOutputStream;
|
||||
import java.io.ObjectStreamClass;
|
||||
import java.io.Serializable;
|
||||
import java.net.UnixDomainSocketAddress;
|
||||
import java.nio.file.Path;
|
||||
import static java.io.ObjectStreamConstants.*;
|
||||
import static org.testng.Assert.assertEquals;
|
||||
import static org.testng.Assert.assertTrue;
|
||||
import static org.testng.Assert.expectThrows;
|
||||
|
||||
/*
|
||||
* @test
|
||||
* @summary UnixDomainSocketAddress serialization test
|
||||
* @run testng/othervm UnixDomainSocketAddressSerializationTest
|
||||
*/
|
||||
|
||||
@Test
|
||||
public class UnixDomainSocketAddressSerializationTest {
|
||||
private static final UnixDomainSocketAddress addr =
|
||||
UnixDomainSocketAddress.of(Path.of("test.sock"));
|
||||
|
||||
public static void test() throws Exception {
|
||||
assertTrue(addr instanceof Serializable);
|
||||
|
||||
byte[] serialized = serialize(addr);
|
||||
assertTrue(serialized.length > 0);
|
||||
|
||||
UnixDomainSocketAddress deserialized =
|
||||
deserialize(serialized, UnixDomainSocketAddress.class);
|
||||
assertEquals(deserialized.getPath(), addr.getPath());
|
||||
assertEquals(deserialized.toString(), addr.toString());
|
||||
assertEquals(deserialized.hashCode(), addr.hashCode());
|
||||
assertEquals(deserialized, addr);
|
||||
}
|
||||
|
||||
static final Class<InvalidObjectException> IOE = InvalidObjectException.class;
|
||||
static final Class<NullPointerException> NPE = NullPointerException.class;
|
||||
|
||||
/** Tests that UnixDomainSocketAddress in the byte-stream is disallowed. */
|
||||
public static void testUnixDomainSocketAddressInStream() throws Exception {
|
||||
long suid = ObjectStreamClass.lookup(UnixDomainSocketAddress.class).getSerialVersionUID();
|
||||
byte[] bytes = byteStreamFor(UnixDomainSocketAddress.class.getName(), suid);
|
||||
expectThrows(IOE, () -> deserialize(bytes, UnixDomainSocketAddress.class));
|
||||
}
|
||||
|
||||
/** Tests that SerialProxy with a null/absent path value in the byte-stream is disallowed. */
|
||||
public static void testSerialProxyNoStreamValues() throws Exception {
|
||||
Class<?> c = Class.forName("java.net.UnixDomainSocketAddress$Ser");
|
||||
long suid = ObjectStreamClass.lookup(c).getSerialVersionUID();
|
||||
byte[] bytes = byteStreamFor(c.getName(), suid);
|
||||
expectThrows(NPE, () -> deserialize(bytes, UnixDomainSocketAddress.class));
|
||||
}
|
||||
|
||||
private static <T extends Serializable> byte[] serialize(T t)
|
||||
throws IOException {
|
||||
ByteArrayOutputStream bos = new ByteArrayOutputStream();
|
||||
ObjectOutputStream oos = new ObjectOutputStream(bos);
|
||||
oos.writeObject(t);
|
||||
oos.flush();
|
||||
oos.close();
|
||||
return bos.toByteArray();
|
||||
}
|
||||
|
||||
private static <T extends Serializable> T deserialize(byte[] b, Class<T> cl)
|
||||
throws IOException, ClassNotFoundException {
|
||||
try (ObjectInputStream ois =
|
||||
new ObjectInputStream(new ByteArrayInputStream(b))) {
|
||||
Object o = ois.readObject();
|
||||
return cl.cast(o);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns a stream with the given classname and suid. The stream will have
|
||||
* no stream field values.
|
||||
*/
|
||||
static byte[] byteStreamFor(String classname, long suid) throws Exception {
|
||||
ByteArrayOutputStream baos = new ByteArrayOutputStream();
|
||||
DataOutputStream dos = new DataOutputStream(baos);
|
||||
dos.writeShort(STREAM_MAGIC);
|
||||
dos.writeShort(STREAM_VERSION);
|
||||
dos.writeByte(TC_OBJECT);
|
||||
dos.writeByte(TC_CLASSDESC);
|
||||
dos.writeUTF(classname);
|
||||
dos.writeLong(suid);
|
||||
dos.writeByte(SC_SERIALIZABLE);
|
||||
dos.writeShort(0); // number of stream fields
|
||||
dos.writeByte(TC_ENDBLOCKDATA); // no annotations
|
||||
dos.writeByte(TC_NULL); // no superclasses
|
||||
dos.write(TC_ENDBLOCKDATA); // end block - for SC_WRITE_METHOD
|
||||
dos.close();
|
||||
return baos.toByteArray();
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue