This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 11.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 947b2d0e53f60b14935519ab5d9c6456477e2dfd Author: opencode <[email protected]> AuthorDate: Wed Sep 30 13:40:25 2026 +0200 Validate the incoming entry at the start of NamingResourcesImpl.addEnvironment() so that an entry which is ignored or rejected cannot first destroy the existing environment entry or resource link with the same name --- .../catalina/deploy/NamingResourcesImpl.java | 44 ++++++++++++---------- 1 file changed, 24 insertions(+), 20 deletions(-) diff --git a/java/org/apache/catalina/deploy/NamingResourcesImpl.java b/java/org/apache/catalina/deploy/NamingResourcesImpl.java index 9d15e54666..e97f1706e9 100644 --- a/java/org/apache/catalina/deploy/NamingResourcesImpl.java +++ b/java/org/apache/catalina/deploy/NamingResourcesImpl.java @@ -236,6 +236,30 @@ public class NamingResourcesImpl extends LifecycleMBeanBase implements Serializa @Override public void addEnvironment(ContextEnvironment environment) { + List<InjectionTarget> injectionTargets = environment.getInjectionTargets(); + String value = environment.getValue(); + String lookupName = environment.getLookupName(); + + // Validate the new entry before any existing entry is removed below. + // Otherwise, an invalid new entry would silently destroy a valid + // existing one. + + // Entries with injection targets but no value are effectively ignored + if (injectionTargets != null && !injectionTargets.isEmpty() && (value == null || value.isEmpty())) { + return; + } + + // Entries with lookup-name and value are an error (EE.5.4.1.3) + if (value != null && !value.isEmpty() && lookupName != null && !lookupName.isEmpty()) { + throw new IllegalArgumentException( + sm.getString("namingResources.envEntryLookupValue", environment.getName())); + } + + if (!checkResourceType(environment)) { + throw new IllegalArgumentException( + sm.getString("namingResources.resourceTypeFail", environment.getName(), environment.getType())); + } + if (entries.contains(environment.getName())) { ContextEnvironment ce = findEnvironment(environment.getName()); ContextResourceLink rl = findResourceLink(environment.getName()); @@ -265,26 +289,6 @@ public class NamingResourcesImpl extends LifecycleMBeanBase implements Serializa } } - List<InjectionTarget> injectionTargets = environment.getInjectionTargets(); - String value = environment.getValue(); - String lookupName = environment.getLookupName(); - - // Entries with injection targets but no value are effectively ignored - if (injectionTargets != null && !injectionTargets.isEmpty() && (value == null || value.isEmpty())) { - return; - } - - // Entries with lookup-name and value are an error (EE.5.4.1.3) - if (value != null && !value.isEmpty() && lookupName != null && !lookupName.isEmpty()) { - throw new IllegalArgumentException( - sm.getString("namingResources.envEntryLookupValue", environment.getName())); - } - - if (!checkResourceType(environment)) { - throw new IllegalArgumentException( - sm.getString("namingResources.resourceTypeFail", environment.getName(), environment.getType())); - } - entries.add(environment.getName()); synchronized (envs) { --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
