GerardGao opened a new pull request, #16437:
URL: https://github.com/apache/dubbo/pull/16437
## What is the purpose of the change
hessian-lite 3.2.x resolves classes that declare a `writeReplace()` method
directly to `JavaSerializer`, before `getDefaultSerializer()` is ever
consulted. Such classes therefore skipped the `checkSerializable()` security
check entirely: a class that does **not** implement `Serializable` could be
serialized as long as it declared `writeReplace()` (verified against 3.2 with a
reproduction test). This is the serialization security bypass reported in
#16287.
The 3.3 line is unaffected (hessian-lite 4.0.5 checks the original class in
the `writeReplace` branch).
## Brief changelog
- `Hessian2SerializerFactory` registers a pre-flight
`AbstractSerializerFactory` via `addFactory` that applies the existing
`checkSerializable()` to classes carrying a `writeReplace()` method, then
returns null so the normal `SerializerFactory` resolution chain keeps control.
- The check mirrors the behavior introduced for `writeReplace` classes in
hessian-lite 4.x, scoped to the 3.2 line.
## Verifying this change
- New `Hessian2WriteReplaceSecurityTest`:
- a non-`Serializable` class with `writeReplace()` is rejected;
- a `Serializable` class whose `writeReplace()` returns a
non-`Serializable` holder is rejected;
- a `Serializable` class whose `writeReplace()` returns a `String` still
serializes (no false positives).
- `mvn -pl dubbo-serialization/dubbo-serialization-hessian2 -am test`: 811
tests, 0 failures.
- `spotless:check` passes; new patch lines are 100% covered.
<!-- Follow this checklist to help us incorporate your contribution quickly
and easily: -->
## Checklist
- [x] Make sure there is a
[GitHub_issue](https://github.com/apache/dubbo/issues) field for the change
(usually before you start working on it). Trivial changes like typos do not
require a GitHub issue. Your pull request should address just this issue,
without pulling in other changes - one PR resolves one issue.
- [x] Each commit in the pull request should have a meaningful subject line
and body.
- [x] Write a pull request description that is detailed enough to understand
what the pull request does, how, and why.
- [ ] Check if is necessary to patch to Dubbo 3 if you are work on Dubbo 2.7
- [x] Write necessary unit-test to verify your logic correction, more mock a
little better when cross module dependency exist. If the new feature or
significant change is committed, please remember to add sample in [dubbo
samples](https://github.com/apache/dubbo-samples) project.
- [ ] Add some description to
[dubbo-website](https://github.com/apache/dubbo-website) project if you are
requesting to add a feature.
- [ ] GitHub Actions works fine on your own branch.
- [ ] If this contribution is large, please follow the [Software Donation
Guide](https://github.com/apache/dubbo/wiki/Software-donation-guide).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]