On Wed, 2 Sep 2026 12:44:06 GMT, Timofei Fedotov <[email protected]> wrote:

>> Rfc2253Parser silently accepted an empty RDN (no attributeTypeAndValue pair) 
>> instead of
>> throwing InvalidNameException. Rdn.getType()/getValue() then indexed an empty
>> internal list, throwing an uncaught IndexOutOfBoundsException instead of the 
>> documented
>> exception.
>> 
>> Two independent entry points:
>> 
>> Rdn("") - the original fuzzer-found crash.
>> LdapName("cn=x,") / LdapName.add("") - a string with a trailing , or ;, 
>> which never goes
>> through Rdn(String) at all (LdapName builds the RDN directly via 
>> Rfc2253Parser).
>> 
>> Add one check, rdn.size() == 0, throw InvalidNameException, placed in
>> 
>> Rfc2253Parser.doParse(Rdn) - the single method both paths funnel through.
>> 
>> Also add a regression check that "cn=a,,cn=b" still throws as before.
>> 
>> 
>> 
>> 
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the 
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Timofei Fedotov has updated the pull request incrementally with one 
> additional commit since the last revision:
> 
>   Add regression test

src/java.naming/share/classes/javax/naming/ldap/Rfc2253Parser.java line 134:

> 132:             // IndexOutOfBoundsException instead of the documented
> 133:             // InvalidNameException.
> 134:             if (rdn.size() == 0) {

`javax.naming.ldap.Rdn` is a public exported class which means that it can be 
overridden by (external/application) sub-classes. The `size()` method is public 
too (and thus can be overridden). I think it would be better to avoid calling 
this method here and instead we should probably call a package-private method 
which returns the same detail. 

So I think introducing something like the following new package-private method 
in `Rdn` class and then calling `rdn.numAttributes()` here might be better:


diff --git a/src/java.naming/share/classes/javax/naming/ldap/Rdn.java 
b/src/java.naming/share/classes/javax/naming/ldap/Rdn.java
--- a/src/java.naming/share/classes/javax/naming/ldap/Rdn.java
+++ b/src/java.naming/share/classes/javax/naming/ldap/Rdn.java
@@ -248,6 +248,15 @@ void sort() {
         }
     }
 
+    /**
+     * {@return the number of type/value mappings contained in this Rdn}
+     * This method is same as {@link #size()}, except that it cannot be
+     * overridden by sub-classes.
+     */
+    final int numAttributes() {
+        return this.entries.size();
+    }
+

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/32648#discussion_r4024771092

Reply via email to