RFR: 8377992: (zipfs) Align ZipFileSystem END header validation with the ZipFile implementation [v3]
Lance Andersen
lancea at openjdk.org
Fri Feb 27 21:43:45 UTC 2026
On Fri, 20 Feb 2026 18:28:54 GMT, Eirik Bjørsnøs <eirbjo at openjdk.org> wrote:
>> Please review this PR which brings `jdk.nio.zipfs.ZipFileSystem` `END` header validation into behavioral alignment with the corresponding checks in `java.util.zip.ZipFile`.
>>
>> This brings two validation checks over to `ZipFileSystem`:
>>
>> * Rejection of END headers with a CEN size larger than `ArraysSupport.SOFT_MAX_ARRAY_LENGTH` (JDK-8272746)
>> * Rejection of END headers with a total entry count which cannot fit within the CEN byte array (JDK-8341625)
>>
>> Test vector setup in `test/jdk/java/util/zip/ZipFile/EndOfCenValidation.java` is extracted to a new test lib utility class `jdk.test.lib.util.ZipUtils`. `EndOfCenValidation` is then copied to `test/jdk/jdk/nio/zipfs` and adjusted to test `ZipFileSystem` instead of `ZipFile`.
>>
>> Tangentially, `ZipFileSystem.findEND` is updated to make `END.centot` a `long` instead of an `int`. This avoids a narrowing conversion which otherwise prevents validating a larger than Integer.MAX_VALUE number of CEN entries. Similar adjustments to `ZipFile` was done in JDK-8341625.
>>
>> `ZipFile.Source.initCEN` is updated with some minor code style / code comment changes to make side-by-side diffs less noisy. Additionally, validated `end.cenlen` and `end.centot` values are now consistently converted to `int` using `Math.toIntExact`.
>
> Eirik Bjørsnøs has updated the pull request incrementally with one additional commit since the last revision:
>
> Dial down on blank lines as vertical space
Marked as reviewed by lancea (Reviewer).
-------------
PR Review: https://git.openjdk.org/jdk/pull/29747#pullrequestreview-3869202563
More information about the core-libs-dev
mailing list