On Wed, 16 Sep 2026 11:34:47 GMT, Timofei Fedotov <[email protected]> wrote:
>> Rfc2253Parser silently accepted an empty RDN (no attributeTypeAndValue pair)
>> instead of
>> throwing InvalidNameException. Rdn.getType()/getValue() then indexed an empty
>> internal list, throwing an uncaught IndexOutOfBoundsException instead of the
>> documented
>> exception.
>>
>> Two independent entry points:
>>
>> Rdn("") - the original fuzzer-found crash.
>> LdapName("cn=x,") / LdapName.add("") - a string with a trailing , or ;,
>> which never goes
>> through Rdn(String) at all (LdapName builds the RDN directly via
>> Rfc2253Parser).
>>
>> Add one check, rdn.size() == 0, throw InvalidNameException, placed in
>>
>> Rfc2253Parser.doParse(Rdn) - the single method both paths funnel through.
>>
>> Also add a regression check that "cn=a,,cn=b" still throws as before.
>>
>>
>>
>>
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Timofei Fedotov has updated the pull request incrementally with two
> additional commits since the last revision:
>
> - Add new subtests in regression test
> - Add assert in Rdn constructor
src/java.naming/share/classes/javax/naming/ldap/Rdn.java line 184:
> 182: entries = new ArrayList<>(rdn.entries.size());
> 183: entries.addAll(rdn.entries);
> 184: assert !entries.isEmpty();
Here is fine too, but I meant in the constructor above, since `(new
Rfc2253Parser(rdnString)).parseRdn(this)` is supposed to throw when no entries
are added
-------------
PR Review Comment: https://git.openjdk.org/jdk/pull/32648#discussion_r4025979789