java-topology/test/jdk/com/sun/net/httpserver/bugs/ExceptionKeepAlive.java
russell@unturf.com 0a580b313d undefect. CWE-407 — 63 sites patched across 27 ecosystems
Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
2026-03-26 17:11:57 -04:00

134 lines
4.9 KiB
Java

/*
* Copyright (c) 2023, 2026, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import com.sun.net.httpserver.HttpExchange;
import com.sun.net.httpserver.HttpHandler;
import com.sun.net.httpserver.HttpServer;
import jdk.test.lib.net.URIBuilder;
import org.junit.jupiter.api.Test;
import java.io.IOException;
import java.net.HttpURLConnection;
import java.net.InetAddress;
import java.net.InetSocketAddress;
import java.net.Proxy;
import java.net.URL;
import java.util.logging.ConsoleHandler;
import java.util.logging.Handler;
import java.util.logging.Level;
import java.util.logging.Logger;
import static org.junit.jupiter.api.Assertions.*;
import static com.sun.net.httpserver.HttpExchange.RSPBODY_EMPTY;
/*
* @test
* @bug 8219083
* @summary Exceptions thrown from HttpHandler.handle should not close connection
* if response is completed
* @library /test/lib
* @comment We use othervm because this test configures logging handlers
* for the system wide "com.sun.net.httpserver" logger
* @run junit/othervm ${test.main.class}
*/
public class ExceptionKeepAlive {
public static final Logger LOGGER = Logger.getLogger("com.sun.net.httpserver");
private static void setupLogging() {
final Handler handler = new ConsoleHandler();
handler.setLevel(Level.FINEST);
LOGGER.setLevel(Level.FINEST);
LOGGER.addHandler(handler);
}
@Test
void test() throws IOException, InterruptedException {
HttpServer httpServer = startHttpServer();
int port = httpServer.getAddress().getPort();
try {
URL url = URIBuilder.newBuilder()
.scheme("http")
.loopback()
.port(port)
.path("/firstCall")
.toURLUnchecked();
HttpURLConnection uc = (HttpURLConnection)url.openConnection(Proxy.NO_PROXY);
int responseCode = uc.getResponseCode();
assertEquals(200, responseCode, "First request should succeed");
URL url2 = URIBuilder.newBuilder()
.scheme("http")
.loopback()
.port(port)
.path("/secondCall")
.toURLUnchecked();
HttpURLConnection uc2 = (HttpURLConnection)url2.openConnection(Proxy.NO_PROXY);
responseCode = uc2.getResponseCode();
assertEquals(200, responseCode, "Second request should reuse connection");
} finally {
httpServer.stop(0);
}
}
/**
* Http Server
*/
HttpServer startHttpServer() throws IOException {
setupLogging(); // merely for debugging
InetAddress loopback = InetAddress.getLoopbackAddress();
HttpServer httpServer = HttpServer.create(new InetSocketAddress(loopback, 0), 0);
httpServer.createContext("/", new MyHandler());
httpServer.start();
return httpServer;
}
class MyHandler implements HttpHandler {
volatile int port1;
@Override
public void handle(HttpExchange t) throws IOException {
String path = t.getRequestURI().getPath();
if (path.equals("/firstCall")) {
port1 = t.getRemoteAddress().getPort();
System.out.println("First connection on client port = " + port1);
// send response
t.sendResponseHeaders(200, RSPBODY_EMPTY);
// response is completed now; throw exception
throw new NumberFormatException();
// the connection should still be reusable
} else if (path.equals("/secondCall")) {
int port2 = t.getRemoteAddress().getPort();
System.out.println("Second connection on client port = " + port2);
if (port1 == port2) {
t.sendResponseHeaders(200, RSPBODY_EMPTY);
} else {
t.sendResponseHeaders(500, RSPBODY_EMPTY);
}
}
t.close();
}
}
}