8367049: URL.openConnection throws StringIndexOutOfBoundsException in avm mode #27896
+81
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Constructing URLPermission with an empty/missing host in the authority (e.g.,
"http:///path"
) could throwStringIndexOutOfBoundsException
.Problem
Empty or malformed authorities reach HostPortrange, which does
charAt(0)
without checking, causingStringIndexOutOfBoundsException
.Fix
URLPermission.Authority
: after stripping userinfo, fail fast if host part is empty.HostPortrange
: add guards for null/empty input and leading ':' (port without host).HttpURLConnection
changes needed in JDK 26 (theSecurityManager
permission path is gone).Compatibility
Only affects malformed inputs: previously
StringIndexOutOfBoundsException
, nowIllegalArgumentException
. Valid inputs unaffected.Testing
New jtreg test:
test/jdk/java/net/URLPermission/EmptyAuthorityTest.java
verifiesIllegalArgumentException
for malformed authorities and success for valid ones.Progress
Error
Issue
Reviewing
Using
git
Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/27896/head:pull/27896
$ git checkout pull/27896
Update a local copy of the PR:
$ git checkout pull/27896
$ git pull https://git.openjdk.org/jdk.git pull/27896/head
Using Skara CLI tools
Checkout this PR locally:
$ git pr checkout 27896
View PR using the GUI difftool:
$ git pr show -t 27896
Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/27896.diff