git: openjdk/jdk: 8300140: ZipFile.isSignatureRelated returns true for files in META-INF subdirectories
Weijun Wang
weijun at openjdk.org
Fri Jan 27 22:49:45 UTC 2023
Changeset: 5dfc4ec7
Author: Eirik Bjorsnos <eirbjo at gmail.com>
Committer: Weijun Wang <weijun at openjdk.org>
Date: 2023-01-27 22:47:51 +0000
URL: https://git.openjdk.org/jdk/commit/5dfc4ec7d94af9fe39fdee9d83b06101b827a3c6
8300140: ZipFile.isSignatureRelated returns true for files in META-INF subdirectories
Reviewed-by: weijun
! src/java.base/share/classes/java/util/jar/JarVerifier.java
! src/java.base/share/classes/java/util/zip/ZipFile.java
! src/java.base/share/classes/sun/security/util/SignatureFileVerifier.java
! src/jdk.jartool/share/classes/jdk/security/jarsigner/JarSigner.java
! src/jdk.jartool/share/classes/sun/security/tools/jarsigner/Main.java
+ test/jdk/java/util/jar/JarFile/IgnoreUnrelatedSignatureFiles.java
More information about the jdk-changes
mailing list